Exploring management approaches to risk
When addressing risk in an organization, there is no one-size-fits-all solution. However, an organization can choose four approaches when responding to a newly discovered risk. Understanding these approaches can help organizations make informed decisions about addressing potential risks. An organization can choose to do the following:
- Mitigate risk: Mitigation involves addressing the root cause of a vulnerability or implementing a compensating security control if the specific issue cannot be resolved. This approach aims to reduce the likelihood or impact of a risk.
Example: Effective patch management is a crucial aspect of any well-functioning IT organization. If a missing patch creates a vulnerability, the system should be patched to mitigate the risk. However, specific IT devices (for example, point-of-sale systems and healthcare devices) may require operating on the enterprise network without regular patching due to vendor limitations...